Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
1 malware family

CLMasters

Also known asclmasters

CLMasters is the developer alias associated with a malicious Google Chrome extension, “CL Suite by @CLMasters” (Chrome Web Store ID: jkphinfhmfkckkcnifhjiplhfoiefffl), which masquerades as a Meta Business Suite/Facebook Business Manager utility (e.g., scraping data, removing verification pop-ups, generating 2FA codes) but covertly exfiltrates sensitive authentication and business data. The extension requests broad host access to meta.com and facebook.com and, despite privacy-policy claims that 2FA secrets and Business Manager data remain local, transmits Facebook/Meta TOTP seeds and current one-time codes, Business Manager “People” CSV exports (names, emails, roles/permissions, access status), and Business Manager analytics/intelligence (Business Manager IDs/names, linked ad accounts, connected pages/assets, and billing/payment configuration details). Exfiltration is sent to attacker-controlled infrastructure at getauth[.]pro (notably /api/telemetry.php and /api/validate.php) using a hardcoded bearer token, with an option to forward the same payloads to a Telegram channel via /api/telegram_notify.php. The extension also collects telemetry/fingerprinting data including tab URLs, user agent, OS, timestamps, and public IP (via api.ipify.org). Reporting notes the extension does not steal passwords directly, but stolen TOTP seeds can neutralize 2FA and enable account takeover when combined with passwords obtained elsewhere (e.g., infostealer logs/credential dumps), and the risk can persist after uninstall because seeds and exported business intelligence remain with the actor. The extension was first uploaded March 1, 2025 (last updated March 6, 2025) and had a low install base (reported as ~28–33 users). Associated developer infrastructure includes clmasters[.]pro (privacy policy “Meta Business Suite Tools”) and contact emails info@clmasters[.]pro and privacy@clmasters[.]pro.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics24 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
3 techniques
T1589
Gather Victim Identity Information
T1589.002
Email Addresses
T1590
Gather Victim Network Information
T1590.005
IP Addresses
T1591
Gather Victim Org Information
T1591.002
Business Relationships
TA0001
Initial Access
1 technique
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
T1204
User Execution
TA0003
Persistence
2 techniques
T1176
Software Extensions
T1176.001
Browser Extensions
T1556
Modify Authentication Process
T1556.006
Multi-Factor Authentication
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
T1556.006
Multi-Factor Authentication
TA0006
Credential Access
1 technique
T1556
Modify Authentication Process
T1556.006
Multi-Factor Authentication
TA0009
Collection
2 techniques
T1005
Data from Local System
T1119
Automated Collection
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
T1071.001
Web Protocols
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.